From patchwork Wed Oct 21 07:44:24 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Chris Packham X-Patchwork-Id: 1385621 Return-Path: X-Original-To: incoming-buildroot@patchwork.ozlabs.org Delivered-To: patchwork-incoming-buildroot@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=busybox.net (client-ip=140.211.166.138; helo=whitealder.osuosl.org; envelope-from=buildroot-bounces@busybox.net; receiver=) Authentication-Results: ozlabs.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20161025 header.b=d9ERLPX+; dkim-atps=neutral Received: from whitealder.osuosl.org (smtp1.osuosl.org [140.211.166.138]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4CGZS72x9Gz9sRk for ; Thu, 22 Oct 2020 02:39:51 +1100 (AEDT) Received: from localhost (localhost [127.0.0.1]) by whitealder.osuosl.org (Postfix) with ESMTP id E367086A2E; Wed, 21 Oct 2020 15:39:49 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from whitealder.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id J2lWY8ue+waV; Wed, 21 Oct 2020 15:39:49 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by whitealder.osuosl.org (Postfix) with ESMTP id 4CE0686BA4; Wed, 21 Oct 2020 15:39:49 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from silver.osuosl.org (smtp3.osuosl.org [140.211.166.136]) by ash.osuosl.org (Postfix) with ESMTP id 43FD81BF338 for ; Wed, 21 Oct 2020 15:39:48 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by silver.osuosl.org (Postfix) with ESMTP id 3D6572E4DA for ; Wed, 21 Oct 2020 15:39:48 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from silver.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KCVH03U44y6S for ; Wed, 21 Oct 2020 15:39:43 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.7.6 Received: from mail-pl1-f195.google.com (mail-pl1-f195.google.com [209.85.214.195]) by silver.osuosl.org (Postfix) with ESMTPS id 1BBCE3302F for ; Wed, 21 Oct 2020 07:44:37 +0000 (UTC) Received: by mail-pl1-f195.google.com with SMTP id t18so804562plo.1 for ; Wed, 21 Oct 2020 00:44:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=QT1wS5RJw0RXRfeub1AC6omdyMJ55mUD2BQo9Fz9FWI=; b=d9ERLPX+Z/sg9HZGMaFawYnknXAsTegVZoRzuLJbtbOLFTSmkUW4X/9y2180x5CUaN 0ib5suS3p+1jRRLBw0/Fu/T6DIWZiNKW0h6epI526uQdzNY+sBzzb5NG5dwcALbOrjs5 8Dh94wytoxtDDuDSFGgAa/lBsEwnqTpfaNcQUlIipXK1HwmZCj+i3a4lNU26NfM2Azdo /H00qFkk/fu9BegvDEntLP/JiiBd8aBfYEQZy64tchLfKGJBERVxtETE/iPc+M/+31+l LSgu9pxH1HOo2xKkwg76t9bJE0FAxGNjNEvHY8XdB/aXsZ2rw+15KBJIQusDJynIoAGt 7+zw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=QT1wS5RJw0RXRfeub1AC6omdyMJ55mUD2BQo9Fz9FWI=; b=mDD9vD7R4CEaYe8EFQE6l0ptmHHqg2DpMWqyKiN2sfEjpX5S0oNs7KxrNOClg60+Cc m5ESzpD/d4w+MdbhdaY5X5dYBWW0qBQIc3dQ93cXMLk0l5W30X/SAR1CYMlaeCzGEEDu aqE8DD9Plvqdp++ZTKTZyfXRE3CDtneByXeZ33QrXGzjENjXlGvYX0DtQz8haSk4yTAL 2GKV4InYD1e/q7V5VUzg3dCW0FFV3Sh5HCOiZC6SJFebDLT/Hn3tWSIcduL33zZWoiEd BdWentGl2FAffLqFCA7UVADaZ2Nt/kZ3gu5lgQfYN1oV+cEJjDVwBS76YxWPbpozFCbP Iijw== X-Gm-Message-State: AOAM5330b46Y8W/J2k06UvyIA+YObMiNHCEd0ih7xggLb40y+qQafh0x I1hU7al6yG4yEjvfMAgAgog1+vvHnaUMgQ== X-Google-Smtp-Source: ABdhPJwsoaNCPKyPP1GYf7nYICktlJ43WNeYO0OdZQ0U5/GmP9QVpPvQbVOJwrgFKRXsd0uXXCNj/g== X-Received: by 2002:a17:902:e782:b029:d2:ac14:2a8d with SMTP id cp2-20020a170902e782b02900d2ac142a8dmr2277820plb.82.1603266276131; Wed, 21 Oct 2020 00:44:36 -0700 (PDT) Received: from chrisp-dl.atlnz.lc ([2001:df5:b000:22:8106:6bf0:aff6:393]) by smtp.gmail.com with ESMTPSA id z5sm1261224pfn.20.2020.10.21.00.44.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 21 Oct 2020 00:44:35 -0700 (PDT) From: Chris Packham To: buildroot@buildroot.org Date: Wed, 21 Oct 2020 20:44:24 +1300 Message-Id: <20201021074424.13589-1-judge.packham@gmail.com> X-Mailer: git-send-email 2.28.0 MIME-Version: 1.0 Subject: [Buildroot] [PATCH] package/syslog-ng: Ignore CVE-2008-5110 X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Chris Packham Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" This as fixed in syslog-ng 2.0.10 but the NVD database hasn't been updated. Signed-off-by: Chris Packham --- package/syslog-ng/syslog-ng.mk | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/package/syslog-ng/syslog-ng.mk b/package/syslog-ng/syslog-ng.mk index 7c2368efba..8587da746a 100644 --- a/package/syslog-ng/syslog-ng.mk +++ b/package/syslog-ng/syslog-ng.mk @@ -17,6 +17,10 @@ SYSLOG_NG_AUTORECONF = YES SYSLOG_NG_CONF_OPTS = --disable-manpages --localstatedir=/var/run \ --disable-java --disable-java-modules --disable-mongodb +# CVE-2008-5110 was fixed in syslog-ng 2.0.10 but the NVD database is not +# aware of the fix, ignore it +SYSLOG_NG_IGNORE_CVES += CVE-2008-5110 + ifeq ($(BR2_PACKAGE_GEOIP),y) SYSLOG_NG_DEPENDENCIES += geoip SYSLOG_NG_CONF_OPTS += --enable-geoip